Scan OpenClaw skills before you trust them.
A skill is markdown that tells your agent what to do, and attackers hide installers and credential grabs inside it. Ironheights reads skill files as data, flags risky patterns with fixed rules, can fetch a ClawHub skill and install it only if the scan is clean, and tells you when an installed skill or agent file changes. It never runs what it scans, makes no network call during a scan, and sends no telemetry.
Free and open source under Apache-2.0. Version 0.3.0 on npm with a provenance signature. No findings means the rules did not match, not that a skill is safe. See what is new in 0.3.0.
Install only from the official sources. Fake “security” skills are a known lure.
The problem
Skills are an attack surface, and the payload is often plain text.
New in 0.3.0
Runs next to the security tools you already have.
Most agents that care about security already run another scanner or guard. Ironheights now finds them, shows where the two would collide, and keeps its own guard from blocking over them. It reads files only and changes nothing.
New in 0.2.0
Protection beyond scanning.
The 0.2.0 release added checks before you install a skill, while your agent runs, and after something changes. Each one says what it does and where it stops.
The foundation
A scanner, a baseline, and a quarantine. Local by default.
How it works
Three commands. Then you decide.
Benchmark #1
What a small test of our own shows. In counts, not percentages.
On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.
Each bar has one segment per sample: 10 malicious and 10 benign skills, 20 in all. Ironheights adds up finding scores: 15 or more is review, 80 or more is block.
Pricing
The scanner is free. Paid tiers are still a plan.
Community is free and open source today. Pro and Team are on the roadmap, and the prices below are early hypotheses we are testing with users. Nothing paid is on sale yet.
Limitations
What Ironheights cannot see.
FAQ
Questions worth asking a security tool.
A free, open-source command-line scanner and integrity monitor for OpenClaw skills. It flags risky patterns in skill files and reports changes to installed skills and agent files against a baseline you save on your machine.
No. No findings means the rules did not match. Novel, heavily obfuscated, or runtime-only attacks can still get through. Read the skill and treat a clean scan as one signal.
Not during a scan. Scans run locally, there is no telemetry, and no scan makes a network call. Only commands you run on purpose, such as safe-install, advisories update, or the optional model review, use the network. The files it scans are read as data and never executed.
Yes. npx ironheights safe-install owner/slug downloads a ClawHub skill, scans it, and installs it only when the verdict is no-findings. A clean result is not proof of safety, so read what you install.
Run npx ironheights scan with the path to a skill, or install the command globally with npm install -g ironheights. It needs Node.js 20 or newer and runs on macOS, Linux, and Windows. The command is also available as ih.
Only from the ironheights package on npm, the GitHub releases of Frank-Masciopinto/ironheights, or links on ironheights.dev. Copycat “security” skills are a known lure.
Community is free. Pro and Team tiers are planned, and the prices on the pricing page are hypotheses. Nothing paid is on sale yet.